ASUS Fixes Another Severe Security Flaw In Armoury Crate, Update ASAP

https://hothardware.com/contentimages/NewsItem/71374/content/16x9_2133x1200_highres-asus-rog-ally-armoury-crate-nebula-background.jpg

ASUS has patched another serious security vulnerability in Armoury Crate and several other hardware-management utilities that could let an unprivileged application gain kernel-level access on Windows systems. The vulnerability, tracked as CVE-2026-8917, carries a CVSS score of 8.4 and affects an ASUS kernel driver that exposes an IOCTL interface to user-mode applications. The nasty bit is that the interface allows an attacker to perform an arbitrary memory write. In other words, an application that shouldn't have any business messing with kernel memory can tell the ASUS driver what address to write to and what data to put there.

Since that driver is running in the Windows kernel, it becomes a rather powerful primitive for escalating privileges. The affected component is used by Armoury Crate, as well as other ASUS utilities including GPU Tweak and AI Suite 3. ASUS has released updated versions of most of these apps, so if...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE